System and method for multi-factor authentication using device tracking and authentication
By monitoring the NFC link status and GPS location of user cards on mobile devices and generating timestamps to achieve multi-factor authentication, the technology addresses the shortcomings in security and user experience in existing technologies, thereby improving the security and fraud prevention capabilities of electronic transactions.
Patent Information
- Application Number
- CN202480018648.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-01-13
- Filing Date
- 2024-01-12
- Publication Date
- 2025-10-31
AI Technical Summary
Existing electronic transaction authentication methods based on user mobile devices rely on user input, have limited security and poor user experience, and lack multi-factor authentication mechanisms.
By setting an external card pocket on a mobile device, the proximity of the user card and GPS location are monitored using an NFC link, a timestamp is generated and compared with the transaction timestamp, thus achieving multi-factor authentication.
It enhances the security of electronic transactions, provides additional authentication factors to prevent fraudulent transactions, and improves the user experience.
Smart Images

Figure CN120883233A_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] This application claims priority to U.S. Patent Application No. 18 / 096,881, filed January 13, 2023, the disclosure of which is incorporated herein by reference in its entirety. Technical Field
[0003] This disclosure generally relates to device proximity detection based on near-field communication, and more specifically to the implementation of device tracking and authentication functions based on device proximity detection for multi-factor authentication. Background Technology
[0004] Electronic transactions initiated by smart cards and / or mobile device applications typically involve single-factor authentication based on verification of data stored on the card and / or transmitted in the transaction request message. With the proliferation of smartphones, some authentication methods incorporate secondary user device verification routines into the authentication process as an additional security measure to prevent fraud by requiring users to verify the card initiated via the corresponding user mobile device.
[0005] However, these methods involve user-provided identification data input via a secondary device and are hampered by limited authentication security. Furthermore, for security and user experience purposes, implementation relying on user-provided input authentication information may be suboptimal.
[0006] These and other shortcomings exist. Therefore, there is a need for secure, user-friendly multi-factor authentication systems and methods. Summary of the Invention
[0007] One aspect of this disclosure relates to proximity monitoring for multi-factor transaction authentication of a user card via a mobile application. This process can be facilitated by an external card storage component that places the card within the Near Field Communication (NFC) field of a mobile device running a link monitoring and location tracking application. Therefore, one aspect of the proposed solution may involve a method comprising the steps of: providing an external card pocket to a user-associated mobile device, the external card pocket being configured to store the user card within the NFC field of the mobile device; monitoring the connection status of an established NFC link between the user card placed in the card pocket and the mobile device via a user application stored on the mobile device; generating one or more event timestamps associated with one or more detection events, wherein each detection event corresponds to a change in the connection status of the NFC link; comparing the latest event timestamp from the one or more event timestamps with a transaction timestamp associated with a transaction request message for a transaction initiated by the user card via a verification process, wherein the one or more event timestamps are transmitted by the user application to the verification process; verifying that the transaction timestamp does not exceed a predefined threshold beyond the latest event timestamp, wherein the latest event timestamp corresponds to the removal of the card from the card pocket.
[0008] According to some embodiments of this disclosure, the method may further include recording GPS location coordinates corresponding to the Global Positioning System (GPS) location of the mobile device at each of one or more event timestamps. The verification process can then generate a multi-factor strong transaction verification response based on verification of the merchant's location from the GPS location of the mobile device associated with the latest event timestamp and a comparison of the latest event timestamp with the transaction timestamp.
[0009] One aspect of this disclosure relates to a system for implementing multi-factor transaction authentication based on device proximity monitoring and location tracking. The system includes a structural element for storing a user card within the near-field communication (NFC) range of a mobile device running a user application. The system also includes computer hardware configured to: monitor the connection status of an NFC link established between the user card and the mobile device when the user card is stored in the structural element, via a user application stored on the mobile device; generate one or more event timestamps associated with one or more detection events, wherein each detection event corresponds to a change in the connection status of the NFC link; and compare the latest event timestamp from the one or more event timestamps with a transaction timestamp associated with a transaction request message for a transaction initiated by the user card, wherein the one or more event timestamps are transmitted by the user application to the verification process. The system can then verify that the transaction timestamp does not exceed a predefined threshold, wherein the latest event timestamp corresponds to the removal of the card from the card holder. When the time interval associated with verifying the removal of the card from the card holder does not exceed the predefined threshold, the system can generate a two-factor strong authentication response for the transaction request message based on verifying the proximity of the user card and the mobile device.
[0010] According to some embodiments of this disclosure, the system can also be configured to record GPS location coordinates corresponding to the Global Positioning System (GPS) location of the mobile device at each of one or more event timestamps. The system can then generate a multi-factor strong transaction verification response based on verification of the merchant location from the GPS location of the mobile device associated with the latest event timestamp and a comparison of the latest event timestamp with the transaction timestamp.
[0011] One aspect of this disclosure relates to a non-transitory computer-accessible medium having stored computer-executable instructions thereon for implementing multi-factor transaction authentication based on card proximity and location tracking data. Attached Figure Description
[0012] Figure 1A Exemplary interactions between a contactless card and a mobile device based on continuous short-range link monitoring according to some embodiments of the present disclosure are shown.
[0013] Figure 1B An exemplary structure of a pocket device having an interaction for implementing continuous short-range link monitoring, according to some embodiments of the present disclosure, is shown.
[0014] Figure 2A Exemplary improved devices and device configurations for implementing continuous card tracking based on NFC link monitoring according to some embodiments of the present disclosure are shown.
[0015] Figure 2B An overview of exemplary timestamp operations for generating card tracking data according to some embodiments of this disclosure is shown.
[0016] Figure 3 An embodiment of an improved device configuration for implementing multi-factor transaction authentication functionality is shown, according to some embodiments of the present disclosure.
[0017] Figure 4 A flowchart is shown illustrating a process for providing two-factor strong transaction authentication capability using proximity event timestamps based on NFC link state monitoring, according to some embodiments of the present disclosure.
[0018] Figure 5 A flowchart is shown illustrating a process for providing three-factor strong transaction authentication capabilities using GPS location data in conjunction with NFC link state monitoring, according to some embodiments of this disclosure.
[0019] Figure 6 This is an illustration of an exemplary block diagram of an exemplary system according to some embodiments of the present disclosure. Detailed Implementation
[0020] The following description of the embodiments provides non-limiting representative examples of reference numerals to specifically describe the features and teachings of different aspects of the invention. The described embodiments should be considered as being practiced alone or in combination with other embodiments described herein. Those skilled in the art who read the description of the embodiments should be able to learn and understand the different descriptive aspects of the invention. The description of the embodiments is intended to promote an understanding of the invention to the extent that other implementations not specifically covered but within the knowledge of those skilled in the art upon reading the description of the embodiments will be understood to be consistent with the application of the invention.
[0021] In one aspect, the disclosed systems and methods aim to enhance the practicality of fraud prevention for contactless one-time password (OTP) card transactions by incorporating an additional layer of authentication security into the corresponding back-end verification process. This enhancement is facilitated by maintaining continuous near-field communication (NFC) contact between the mobile device and the contactless card using an external cardholder attached to the mobile device. This enables the mobile device to report the card's location to the back-end verification process based on the detected NFC link status. The proposed apparatus includes a mobile device with a cardholder for storing the contactless OTP card within the NFC range of a mobile device reader, which enables back-end tracking of card activity relative to its proximity to a secondary user device (e.g., a mobile phone). This provides a second authentication factor for transactions using contactless OTP cards without requiring secondary authentication input from the user.
[0022] The disclosed physical means and operating configuration for operating contactless OTP cards within the NFC range of a mobile communication device (e.g., by using a card sleeve that overlaps with the communication field emitted from a reader of the mobile communication device) also provide proactive reporting of card location based on the ON / OFF state of the NFC link (e.g., corresponding to the insertion and removal of the card from the card sleeve), which further provides card tracking utility in the event of card loss and / or theft.
[0023] Figure 1A An overview of the interaction between the mobile device (102) and the user card (104) is shown. Communication between the two devices (e.g., the mobile device (102) and the card (104)) is proximity-based and enabled across an NFC link (106) established for the user card (104) to enter an NFC field, for example, generated by the reader component (103) of the mobile device (102). The NFC tag on the user card can then communicate with the mobile device while within the NFC proximity of the mobile device's reader. A corresponding user application (108) running on the mobile device can then receive and process the data transmitted via NFC. The NFC field can be generated by the mobile device (e.g., a smartphone), a point-of-sale device, or other devices. Data (107) retrieved by the user application (108) can correspond to the connection status of the NFC link (106), conveying an active or inactive state indicating the presence or absence of the card within the proximity of the mobile device (102).
[0024] Figure 1BAn exemplary rear view illustration (125) of an improved device (120) is shown, which includes a mobile device accessory characterized by a card storage compartment and / or pocket (e.g., a card sleeve / storage assembly (122)) storing an NFC-readable card (104) and can be used to operatively integrate a user mobile device (102) with a user card (104). For example, the active or inactive state of the NFC link (106) can indicate the presence or absence of the card (104) in the card sleeve (122). A change in the connection state of the NFC link (106) from inactive to active can correspond to the insertion of the user card (104) into the card pocket (122). Similarly, a change in the NFC link state from active to inactive can correspond to the removal of the user card (104) from the card pocket (122). The corresponding configuration can then be used to implement proximity detection / card tracking and multi-factor transaction authentication functions (e.g., for electronic transactions initiated by a card or mobile device). In some embodiments, the card pouch may correspond to an external storage component attached to a mobile device and configured to place a user card within the near field communication (NFC) field of the mobile device. Thus, the (external) card storage component (also referred to as the card pouch) may be structurally configured to place the NFC tag of the user card (104) in an optimal orientation for establishing a proximity-based NFC link (106) with the NFC reader (103) of the mobile device (102). As illustrated in an exemplary rear view (125) of an improved device (120) with a card sleeve / storage component (122), the user card (104) is oriented in the card pouch (122) such that the NFC tag of the card overlaps with the NFC reader (103) of the mobile device (102). Therefore, an active proximity-based NFC signal is established between the user card (104) (e.g., the integrated NFC tag of the card) and the mobile device (102) (e.g., the NFC reader component of the mobile device). The rear view (125) shows the overlap of the NFC tag and the NFC reader of the mobile device.
[0025] In some embodiments, a user card (104) stored in a card pouch (106) may correspond to a contactless card. The contactless card may include an integrated processor and memory that can store, for example, user identification and / or authentication information as Near Field Communication (NFC) transferable data (e.g., NFC Data Exchange Format, NDEF)). The integrated memory may store one or more applets communicatively coupled to one or more applications (e.g., application 107) running on the user's mobile and / or computing device (102) and one or more applications stored on a corresponding application server. The card's integrated memory may also store an application transaction counter (CTR) to track the correct sequence of operations associated with transactions performed using the contactless card. The contactless card may also include a Near Field Communication (NFC) interface (e.g., an NFC tag) to facilitate NFC communication with an NFC reader (e.g., a reader component (103) of the mobile device (102)). Then, the mobile user equipment's reader component can directly capture user authentication information by bringing the contactless card into the NFC range of the mobile device (e.g., by storing the contactless card in a card pocket (122) to overlap with the NFC reader (103) of the user's mobile device), in order to, for example, initiate direct reading and subsequent verification of the user authentication information stored on the contactless card as NFC-transferable data.
[0026] As described herein, one embodiment of the aforementioned configuration for operational integration of a user card with one or more applications running on a mobile device may involve, for example... Figure 2AThe card tracking function is shown. As described with reference to Figure 1, the mobile device (102) can maintain a continuous NFC link with the user card (104) as long as the card remains within the NFC proximity range of the mobile device. Therefore, an exemplary card tracking configuration (200) including an improved device (120) with a card pouch (122) enables active and / or continuous monitoring of the NFC link (106) by positioning the card in an orientation that optimizes the NFC connection between the card and the mobile device relative to the NFC reader (103) of the mobile device. When the card is removed from the card pouch (122), the NFC link (106) is disconnected. The mobile user application (208) can use the detection event corresponding to the state change of the NFC link (106) to trigger a set of responses, such as generating a timestamp indicating the time of the NFC link state change, and retrieving geolocation data indicating the location coordinates of the mobile device (102) at the time of the change. The geolocation data can be retrieved from one or more GPS and / or navigation-related applications running on the mobile device. This is illustrated in example (200) by the location request (205) and location response (206) messages exchanged between the (card tracking) user application (208) and the GPS application (209) stored on the mobile device.
[0027] Card proximity detection based on active / passive NFC link status monitoring can correspond to the detection of two discrete conditions, namely, detecting NFC link loss when removing the user card (104) from the card holder (122) and detecting an established active NFC link when inserting / re-inserting the card (104) into the card holder (122). As indicated by the data transmission action (107), NFC link monitoring data conveying the connection status of the NFC link is transmitted by and / or retrieved from the NFC reader (103) of the mobile device (102). Upon receiving the NFC link status data, the user mobile application (208) can perform an exemplary timestamp operation (207) to generate card tracking data (210), such as Figure 2B This is further illustrated in the text.
[0028] Figure 2BAn exemplary overview of a timestamping operation (207) is shown, which may involve generating a timestamp for each detection event corresponding to a change in the connection state of the NFC link (106) detected by a user application (208), based on active NFC link monitoring data (107) from an NFC reader. This operation may also involve retrieving location data request messages (205) and geographic location data (206) corresponding to the location of the mobile device, as provided by one or more mobile GPS-based applications (209). As described herein, the aforementioned location data communication may be initiated upon detection of an NFC link state event. The timestamped NFC link state data and the corresponding GPS location data (206) can then be compiled into one or more data structures, as shown in the exemplary card tracking dataset (210). The card tracking data (210) can then be stored by the mobile device and / or transmitted to a remote authentication server to facilitate card tracking and / or multi-factor authentication functionality.
[0029] In some embodiments, card tracking data can be used to identify lost cards and can be used to provide user notifications via, for example, a user's mobile device. In this case, a predefined time window may exist during which the loss of the NFC link might be attributed to the temporary removal of the card from the card holder for a transaction. Therefore, a lost card notification can be generated by a card tracking application (e.g., 208) based on the determination that a timelapse associated with the latest event timestamp exceeds a predefined threshold. Then, based on GPS readings on the mobile device, a notification can be generated and delivered to the user, the notification having a timestamp corresponding to the last recorded location of the card, where the latest GPS location of the mobile device corresponds to the last recorded timestamp. The aforementioned threshold (time window) can be specified by the user or determined by the system and / or the user (mobile) application based on historical geographic tracking and card proximity data. In some embodiments...
[0030] Figure 3 An exemplary embodiment of a device (120) utilizing a card pocket structure (122) in implementing an (improved) transaction authentication process (306) for electronic transactions using a card (104) and, for example, a point-of-sale (POS) device (302) located at a merchant's location is shown. In some embodiments, a transaction request (308) may correspond to an electronic card transaction conducted remotely via, for example, a merchant's website. The foregoing embodiments provide fraud prevention for electronic transactions involving the improved device (120) by confirming the presence of different secondary user devices within the proximity of the user device initiating the transaction.
[0031] In some embodiments, card tracking data (including timestamped NFC link status and GPS location data) generated by the improved device (120) can be used to enable multi-factor authentication of electronic transactions made by the user card (104) and / or mobile device (102). In this case, a predefined time window may exist during which a loss of the NFC link may be attributed to the temporary removal of the card from the card holder for the purpose of making a transaction. Therefore, the second factor verification parameter can be determined based on the following: the delay between the latest event timestamp and the receipt of the incoming card transaction request (308) by the verification server (310) does not exceed a predefined threshold, thereby establishing proximity between the user card (104) and the second user device (e.g., mobile device (102)). The threshold (time window) can be specified by the user or determined by the system and / or user (mobile) application based on historical geographic tracking and card proximity data.
[0032] Return to reference Figure 3 The time interval elapsed between the card retrieval event (309) corresponding to the latest event timestamp (e.g., t4 retrieval of card tracking data (210)) and the receipt of the transaction request message (308) by the verification server (310) can be calculated by an improved verification process (306) running on the receiving verification server (310) and compared with the aforementioned threshold time window. If the retrieval time window (309) based on, for example, the latest event timestamp received via the dataset (210) and the verification server's (310) detection of the transaction request message (308) does not exceed the threshold time window value, a two-factor strong verification response can be generated for the electronic transaction request message (308). In some embodiments, when it is determined that the incoming transaction timestamp exceeds the latest event timestamp by more than a predefined threshold, a notification can be generated and communicated to the user. The notification may also include a timestamp corresponding to the last recorded location of the card based on GPS readings on the mobile device. Therefore, the verification of the transaction request can be suspended until a user confirmation signal is received via the mobile device (102).
[0033] Another embodiment associated with the system implementation (300) may correspond to multi-factor authentication for electronic transaction requests (e.g., transaction request (312)) initiated by a mobile device (102). Referring to the transaction request message (312) initiated by the mobile device, proximity information to a secondary user device (e.g., a card (104)) may be conveyed via card tracking data along with other user and / or account identification information to enhance the security of the authentication process and prevent fraudulent electronic transactions, for example, that could be attempted using stolen user and / or account identification information. Card proximity information (transmitted in the card tracking data) may be provided as an additional factor for authentication. Thus, upon receiving an online transaction request (312), a two-factor strong authentication process may be performed by an improved authentication process (306) based on the determination that the transaction timestamp associated with the online transaction does not exceed the latest event timestamp in the card tracking data (210) by more than a predefined threshold. When it is determined that the transaction timestamp exceeds the latest recorded event timestamp by more than the predefined threshold, a user alert notification may be generated by a user application running on the mobile device.
[0034] Referring to the exemplary embodiment (300), further enhancement of authentication security can be achieved by using GPS location data to geoidentify the merchant's location associated with an incoming transaction request (e.g., a card transaction request (308) and / or a transaction request (312) initiated by a mobile device). The improved verification process (306) can then identify the merchant based on the GPS location data provided in the card tracking data (210) and compare the merchant identification data (determined based on the reported GPS location) with one or more merchant identifiers extracted from the transaction string data (e.g., corresponding to transaction requests (308) and / or (312)). Verification based on the merchant's geoidentification from the GPS location data recorded in the card tracking data and corresponding card proximity data relative to a predefined threshold can be performed in response to an incoming transaction request, using the improved verification process (306) to generate a multi-factor strong verification message (314) corresponding to the three factors of authentication.
[0035] Figure 4An exemplary operational flow for implementing two-factor authentication for electronic transactions based on an improved device configuration (120) is illustrated. The operational flow chart (400) can be applied to electronic transactions initiated by a user card (104) and / or mobile device (102) associated with the improved device configuration (120). The implementation is based on verifying the proximity of another device using out-of-band (OOB) transmission of card proximity data to a transaction verification server (requiring no additional action from the user). The card proximity data can then be used to verify transaction request messages initiated by any of the devices associated with the improved device configuration (120), such as the user card and / or the user's mobile device. Return to Reference Figure 4 At step (402), the exemplary process flow (400) can detect changes in the state of the NFC link established between the user card and the mobile device, and generate an event timestamp in response to the detected event corresponding to a link connection or disconnection. At step (404), when a link disconnection is detected, the application running on the mobile device can transmit a timestamp indicating a change in the NFC link state.
[0036] The verification process for receiving an electronic transaction verification request can verify the electronic transaction string based on data provided in the transaction message (step 406). While authenticating the transaction request string, the verification process can further analyze out-of-band data (e.g., data associated with and / or combined with received data of an electronic transaction not included in the initial transaction string) to confirm, based on the card proximity timestamp, that the time period during which the card has been out of the cardholder does not exceed a predefined threshold. Once the proximity of the card to the mobile device has been determined at step (408) for at least the time period corresponding to the predefined threshold, a two-factor strong transaction verification message can be generated and sent back at step (410) in response to the transaction request. Conversely, if it is determined at step (408) that the card removal timestamp exceeds the threshold, indicating an extended separation period between the user card and the mobile device, the process can move to step (412), where a notification can be sent to the mobile device, and the verification process can be rejected and / or suspended until a user confirmation response is received from the mobile device.
[0037] Figure 5An exemplary operation flowchart (500) is shown for implementing multi-factor authentication using an improved device (120) based on: verification of timestamped NFC link status and GPS location data corresponding to electronic transactions initiated by a user card (104) or a mobile device (102). Transactions can be initiated by a mobile device using, for example, a mobile application with authentication capabilities (such as a banking app and / or an authentication app stored on the mobile device). Transactions can also be initiated by a user card by removing the card from a designated card holder (attached to the mobile device and tapped or swiped at a POS). Card transactions can also correspond to online transactions by entering card information along with any card and / or user authentication data into an online payment interface on a merchant's website. In this case, as previously referenced... Figure 3 and Figure 4 The proximity verification of secondary user devices discussed can be used as a second identifying factor for authenticating electronic transactions. (See reference...) Figure 3 Further discussion could also be conducted on implementing a multi-factor authentication scheme based on an improved equipment configuration (120). Figure 5 A flowchart of an exemplary three-factor transaction authentication scheme (500) is shown, which uses three-factor authentication based on timestamped NFC link status data (for verifying proximity to a secondary user device) and GPS location data provided by card tracking data (for verifying the location of the transaction merchant by comparing it with merchant identification information extracted from the incoming transaction request string).
[0038] Return to reference Figure 5 Step (502) corresponds to detecting NFC link state changes and generating a timestamp associated with the link state event. At step (504), data from a mobile GPS application can be retrieved to determine the physical location of the improved device at the time of the transaction. The operation at step (504) can occur simultaneously or sequentially with the generation of the timestamp indicating the link change state at step (502). The retrieved GPS location data and (link loss) timestamp can be included in the card tracking dataset (step 504). At step (506), the data generated in step (504) can be provided to the verification process, for example, by a mobile authentication application in conjunction with a transaction request initiated by the user card (104) or mobile device (102).
[0039] The verification process for receiving transaction requests and card tracking datasets can first verify the electronic transaction string based on the authentication and / or account data provided in the transaction message (step 508). This step can also correspond to... Figure 4The action associated with step (406) in the process. Upon authenticating the transaction request string, the verification process may move to step (510) to verify proximity data relative to the second user device based on information provided in the card tracking dataset. If the proximity data relative to the second user device is unavailable for a period exceeding a predefined threshold, indicating an extended separation period between the card and the mobile phone, the verification process may initiate one or more actions as indicated in step (512). One or more actions may include, for example, generating a notification to the mobile device to alert the user and / or suspending verification of the transaction request before, for example, receiving a user confirmation signal from the mobile device. However, if proximity data relative to the second user device is verified at step (510), the process may move to step (514).
[0040] At step (514), the card tracking dataset can be further examined to confirm that the corresponding timestamped GPS location data matches the merchant location identified from the transaction request string. If no match is identified, one or more actions associated with step (512) can be performed. However, at step (514), if the GPS location data matches the merchant information extracted from the transaction string, a multi-factor strong verification response (e.g., corresponding to verification of secondary device proximity and transaction initiation location) can be generated in response to the transaction request message.
[0041] In some embodiments, one or more of the aforementioned calculations and operations for card tracking and providing multi-factor authentication based on dynamic NFC link state and mobile GPS location data may be performed, in part or in whole, by one or more applications running on a user's mobile device and / or one or more server-side applications running on a corresponding remote authentication server, which is communicatively coupled across a network to one or more user applications running on the user's mobile device.
[0042] Figure 6 Block diagrams illustrating exemplary embodiments of a system according to this disclosure are shown. For example, exemplary processes of this disclosure as described herein may be executed by a processing means and / or a computing means (e.g., a computer hardware means) (605). Such a processing means and / or computing means (605) may be, for example, all or part of a computer and / or processor (610), or include, but are not limited to, a computer and / or processor (610), which may include, for example, one or more microprocessors, and uses instructions stored on a computer-accessible medium (e.g., RAM, ROM, hard disk drive, or other storage device).
[0043] like Figure 6As shown, for example, a computer-accessible medium (615) (e.g., a storage device, such as a hard disk, floppy disk, memory stick, CD-ROM, RAM, ROM, etc., or a combination thereof, as described above) may be provided (e.g., in communication with the processing device (605)). The computer-accessible medium (615) may contain executable instructions (620) thereon. Alternatively or separately, the storage device (625) may be provided separately from the computer-accessible medium (615), which may provide instructions to the processing device (605) to configure the processing device to perform exemplary processes, procedures, and methods, for example, as described above.
[0044] Furthermore, the exemplary processing device (605) may be equipped with or include input ports and / or output ports (635), which may include, for example, wired networks, wireless networks, the Internet, intranets, data collection probes, sensors, etc. Figure 6 As shown, the exemplary processing device (605) can communicate with the exemplary display device (630), which, according to a specific exemplary embodiment of this disclosure, can be a touchscreen configured to input information to the processing device, for example, in addition to outputting information from the processing device. Furthermore, the exemplary display device (630) and / or storage device (625) can be used to display and / or store data in a user-accessible and / or user-readable format.
[0045] In some aspects, the technology described herein relates to a method for incorporating device proximity monitoring in multi-factor authentication, the method comprising: providing an external card pouch to a mobile device associated with a user, the external card pouch being configured to store a user card within the near field communication (NFC) field of the mobile device; monitoring the connection status of an NFC link established between the user card placed in the card pouch and the mobile device via a user application stored on the mobile device; generating one or more event timestamps associated with one or more detection events, wherein each detection event corresponds to a change in the connection status of the NFC link; comparing the latest event timestamp from the one or more event timestamps with a transaction timestamp associated with a transaction request message for a transaction initiated by the user card via a verification process, wherein the one or more event timestamps are transmitted to the verification process by the user application; verifying that the transaction timestamp does not exceed the latest event timestamp by more than a predefined threshold, wherein the latest event timestamp corresponds to the removal of the card from the card pouch; and generating a two-factor strong verification response for the transaction request message based on verifying the proximity of the user card and the mobile device.
[0046] In some respects, the techniques described herein relate to a method that further includes recording, at each of one or more event timestamps, GPS location coordinates corresponding to the Global Positioning System (GPS) location of the mobile device.
[0047] In some respects, the techniques described herein relate to a method in which the latest GPS location of a mobile device corresponds to the latest recorded timestamp.
[0048] In some respects, the technology described herein relates to a method that also includes verifying, through a verification process, that the latest GPS location of a mobile device corresponds to a merchant location identified from a transaction request message.
[0049] In some respects, the techniques described herein relate to a method that further includes generating a multi-factor strong verification response corresponding to verification of the merchant's location by means of a verification process based on verification of the latest GPS location and the latest event timestamp of the mobile device.
[0050] In some respects, the techniques described herein relate to a method in which a user application includes one or more application components running on a remote verification server associated with the verification process.
[0051] In some respects, the techniques described herein involve a method in which a predefined threshold is specified by the user.
[0052] In some respects, the technology described herein relates to a method in which a transaction request message corresponds to an online transaction initiated from a mobile device.
[0053] In some respects, the technology described herein relates to a method in which, upon receiving an online transaction request, a two-factor strong verification process is performed by a verification process based on the determination that the transaction timestamp associated with the online transaction does not exceed the latest event timestamp by more than a predefined threshold.
[0054] In some respects, the technology described herein relates to a method that also includes generating a user alert notification via a user application running on a mobile device when it is determined that the transaction timestamp exceeds the latest event timestamp by more than a predefined threshold.
[0055] In some respects, the technology described herein relates to a method in which a user alert notification includes the latest GPS location of the user card corresponding to the latest event timestamp.
[0056] In some respects, the techniques described herein relate to a method in which the monitoring corresponds to determining the connection status of an NFC link as active or inactive.
[0057] In some respects, the technology described herein relates to a method in which a change in the connection state of an NFC link from inactive to active corresponds to inserting a user card into a card pocket for storage, and a change in the state of an NFC link from inactive to active corresponds to removing a user card from a card pocket for electronic transactions.
[0058] In some aspects, the technology described herein relates to a system for implementing multi-factor transaction authentication based on device proximity monitoring. The system includes a structural element for storing a user card within the near field communication (NFC) range of a mobile device running a user application. The system also includes computer hardware configured to: monitor the connection status of an NFC link established between the user card and the mobile device when the user card is stored in the structural element, via a user application stored on the mobile device; generate one or more event timestamps associated with one or more detection events, wherein each detection event corresponds to a change in the connection status of the NFC link; compare the latest event timestamp from the one or more event timestamps with a transaction timestamp associated with a transaction request message for a transaction initiated by the user card, wherein the one or more event timestamps are transmitted to the verification process by the user application; verify that the transaction timestamp does not exceed a predefined threshold beyond the latest event timestamp, wherein the latest event timestamp corresponds to the removal of the card from the card holder; and generate a two-factor strong authentication response for the transaction request message based on verifying the proximity of the user card and the mobile device.
[0059] In some respects, the technology described herein relates to a system in which computer hardware is configured to record, at each of one or more event timestamps, GPS location coordinates corresponding to the Global Positioning System (GPS) location of a mobile device.
[0060] In some respects, the technology described herein relates to a system in which hardware is also configured to verify whether GPS location data associated with the latest event timestamp corresponds to a merchant location identified from a transaction request message.
[0061] In some respects, the technology described herein relates to a system in which hardware is also configured to generate a multi-factor strong verification response corresponding to verification of the merchant's location based on verification of the latest GPS location and the latest event timestamp of the mobile device.
[0062] In some aspects, the technology described herein relates to a non-transitory computer-accessible medium including instructions for execution by a computer hardware device, wherein, when executing the instructions, the computer hardware device is configured to perform a process comprising the following steps: monitoring the connection status of an NFC link established between a user card and a mobile device via a user application stored on a mobile device, wherein the user card is stored in an external storage component attached to the mobile device and configured to place the user card within the near field communication (NFC) field of the mobile device; generating one or more event timestamps associated with one or more detection events, wherein each detection event corresponds to a change in the connection status of the NFC link; comparing the latest event timestamp from the one or more event timestamps with a transaction timestamp associated with a transaction request message for a transaction initiated by the user card via a verification process, wherein the one or more event timestamps are transmitted by the user application to the verification process; verifying that the transaction timestamp does not exceed a predefined threshold more than the latest event timestamp, wherein the latest event timestamp corresponds to the removal of the card from the card holder; and generating a two-factor strong verification response for the transaction request message based on verifying the proximity of the user card and the mobile device.
[0063] In some respects, the techniques described herein relate to a non-transitory computer-accessible medium that further includes instructions for recording GPS location coordinates corresponding to the Global Positioning System (GPS) location of a mobile device at each of one or more event timestamps.
[0064] In some respects, the techniques described herein relate to a non-transitory computer-accessible medium that further includes instructions for verifying whether GPS location data associated with a recent event timestamp corresponds to a merchant location identified from a transaction request message.
[0065] As used herein, the term "card" is not limited to a specific type of card. Rather, it is understood that, unless otherwise stated, the term "card" can refer to a contact-based card, a contactless card, or any other card. It should also be understood that this disclosure is not limited to cards for a specific purpose (e.g., payment cards, gift cards, ID cards, membership cards, transportation cards, access cards), cards associated with a specific type of account (e.g., credit accounts, debit accounts, membership accounts), or cards issued by a specific entity (e.g., commercial entities, financial institutions, government entities, social clubs). Rather, it should be understood that this disclosure includes cards for any purpose, account associated with, or issued by any entity.
[0066] This disclosure is not limited to the specific embodiments described herein, which are intended to illustrate various aspects. It will be apparent that many modifications and variations can be made without departing from its spirit and scope. Functionally equivalent methods and apparatuses within the scope of this disclosure may be apparent from the foregoing representative description, in addition to those listed herein. Such modifications and variations are intended to fall within the scope of the appended representative claims. This disclosure is limited only by the terms of the appended representative claims and the full scope of equivalents enjoyed by such representative claims. It should also be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting.
[0067] It should also be noted that the systems and methods described herein can be tangibly embodied in one or more physical media, such as, but not limited to, optical discs (CDs), digital versatile optical discs (DVDs), floppy disks, hard disks, read-only memory (ROM), random access memory (RAM), and other physical media capable of storing data. For example, data storage devices may include random access memory (RAM) and read-only memory (ROM), which can be configured to access and store data and information, as well as computer program instructions. Data storage devices may also include storage media or other suitable types of memory (e.g., such as RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), disks, optical discs, floppy disks, hard disks, removable magnetic tape cassettes, flash drives, any type of tangible and non-transitory storage media), in which files including operating systems, applications including, for example, web browser applications, email applications and / or other applications, and data files can be stored. Data storage devices for network-enabled computer systems may include electronic information, files, and documents stored in various ways, including, for example, flat files, indexed files, hierarchical databases, relational databases, such as those from, for example... The company's software creation and maintenance database, Excel file, Access files, solid-state storage devices (which may include flash arrays, hybrid arrays, or server-side products), enterprise storage (which may include online or cloud storage), or any other storage mechanism. Furthermore, the accompanying drawings illustrate various components (e.g., servers, computers, processors, etc.). Functions described as performing at individual components can be performed at other components, and the components can be combined or separated. Other modifications are also possible.
[0068] Various embodiments have been described in the foregoing description with reference to the accompanying drawings. However, it will be apparent that various modifications and changes can be made thereto, and additional embodiments can be implemented without departing from the broader scope of the invention as set forth in the following claims. Therefore, the description and drawings should be considered illustrative rather than restrictive.
Claims
1. A method for incorporating device proximity monitoring in multi-factor authentication, the method comprising: Provide an external card pocket to a mobile device associated with a user, the external card pocket being configured to store the user card within the near field communication (NFC) field of the mobile device; The connection status of the NFC link established between the user card set in the card pocket and the mobile device is monitored by a user application stored on the mobile device. Generate one or more event timestamps associated with one or more detection events, wherein each detection event corresponds to a change in the connection state of the NFC link; The verification process compares the latest event timestamp from the one or more event timestamps with the transaction timestamp associated with the transaction request message of the transaction initiated by the user card, wherein the one or more event timestamps are transmitted to the verification process by the user application; Verify that the transaction timestamp does not exceed a predefined threshold, wherein the latest event timestamp corresponds to the card being removed from the card holder; and A two-factor strong authentication response for the transaction request message is generated based on verifying the proximity of the user card to the mobile device.
2. The method of claim 1, further comprising recording, at each of the one or more event timestamps, GPS location coordinates corresponding to the Global Positioning System (GPS) location of the mobile device.
3. The method according to claim 2, wherein, The latest GPS location of the mobile device corresponds to the latest recorded timestamp.
4. The method according to claim 3, further comprising: The verification process verifies that the latest GPS location of the mobile device corresponds to the merchant location identified from the transaction request message.
5. The method according to claim 4, further comprising: The verification process generates a multi-factor strong verification response corresponding to the verification of the merchant's location based on the verification of the latest GPS location of the mobile device and the latest event timestamp.
6. The method according to claim 1, wherein, The user application includes one or more application components running on a remote verification server associated with the verification process.
7. The method according to claim 1, wherein, The predefined threshold is specified by the user.
8. The method according to claim 1, wherein, The transaction request message corresponds to an online transaction initiated from the mobile device.
9. The method according to claim 8, wherein, Upon receiving the online transaction request, a two-factor strong verification process is executed by the verification process, which is based on the determination that the transaction timestamp associated with the online transaction does not exceed the latest event timestamp by more than the predefined threshold.
10. The method according to claim 1, further comprising: When it is determined that the transaction timestamp exceeds the latest event timestamp by more than the predefined threshold, a user alert notification is generated through a user application running on the mobile device.
11. The method according to claim 10, wherein, The user alert notification includes the latest GPS location of the user card corresponding to the latest event timestamp.
12. The method according to claim 1, wherein, The monitoring and NFC link connection status is determined as either active or inactive.
13. The method according to claim 12, wherein, The change in the connection state of the NFC link from inactive to active corresponds to inserting the user card into the card pocket for storage, and the change in the state of the NFC link from inactive to active corresponds to removing the user card from the card pocket for electronic transactions.
14. A system for implementing multi-factor transaction authentication based on device proximity monitoring, the system including structural elements for storing a user card within the near field communication (NFC) range of a mobile device running a user application, the system further including computer hardware configured to: The connection status of the NFC link established between the user card and the mobile device when the user card is stored in the structural element is monitored by a user application stored on the mobile device. Generate one or more event timestamps associated with one or more detected events, wherein, Each detection event corresponds to a change in the connection state of the NFC link; The verification process compares the latest event timestamp from the one or more event timestamps with the transaction timestamp associated with the transaction request message of the transaction initiated by the user card, wherein the one or more event timestamps are transmitted to the verification process by the user application; Verify that the transaction timestamp does not exceed a predefined threshold, wherein the latest event timestamp corresponds to the card being removed from the structural element; and A two-factor strong authentication response for the transaction request message is generated based on verifying the proximity of the user card to the mobile device.
15. The system according to claim 14, wherein, The computer hardware is configured to record, at each of the one or more event timestamps, the GPS location coordinates corresponding to the Global Positioning System (GPS) location of the mobile device.
16. The system according to claim 15, wherein, The hardware device is also configured to verify whether the GPS location data associated with the latest event timestamp corresponds to the merchant location identified from the transaction request message.
17. The system according to claim 16, wherein, The hardware device is also configured to generate a multi-factor strong verification response corresponding to the verification of the merchant's location based on the verification of the latest GPS location of the mobile device and the latest event timestamp.
18. A non-transitory computer-accessible medium, comprising instructions for execution by a computer hardware device, wherein, When the instructions are executed, the computer hardware device is configured to perform a process including the following steps: The connection status of the NFC link established between the user card and the mobile device is monitored by a user application stored on the mobile device, wherein the user card is stored in an external storage component attached to the mobile device and configured to place the user card within the near field communication (NFC) field of the mobile device. Generate one or more event timestamps associated with one or more detection events, wherein each detection event corresponds to a change in the connection state of the NFC link; The verification process compares the latest event timestamp from the one or more event timestamps with the transaction timestamp associated with the transaction request message of the transaction initiated by the user card, wherein the one or more event timestamps are transmitted to the verification process by the user application; Verify that the transaction timestamp does not exceed a predefined threshold, wherein the latest event timestamp corresponds to the card being retrieved from the external storage component; and A two-factor strong authentication response for the transaction request message is generated based on verifying the proximity of the user card to the mobile device.
19. The non-transitory computer-accessible medium of claim 18, further comprising instructions for recording GPS location coordinates corresponding to the Global Positioning System (GPS) location of the mobile device at each of the one or more event timestamps.
20. The non-transitory computer-accessible medium of claim 19, further comprising instructions for verifying whether GPS location data associated with the latest event timestamp corresponds to a merchant location identified from the transaction request message.